GLOBAL ยท EUROPE ยท MIDDLE EASTSources
NNews DeskThe world, in headlines.
Image accompanying this story from The Hacker News
Photo: The Hacker News
The Hacker NewsIndia

Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm

The npm package known as "tensorlake," a TypeScript software development kit (SDK) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack. The malicious version 0.5.144 "contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code," Socket said

Read Full Story

Original reporting by The Hacker News. Some articles may require a subscription.